04-27-2004 01:20 PM - edited 03-10-2019 07:46 AM
Can you point me to a configuration guide that would walk me through using my ACS 3.2 Appliance to be the RADIUS authenticator for WIN2K PC's? I'd like to implement 802.1x and the PCs are connected to a 3560 switch. Also if Active Directory could be used that would be great also. - Thanks
05-07-2004 08:17 AM
Any update on this?
05-12-2004 09:06 PM
With 802.1x, there are multiple ways of authenticating win2k machines.
There is EAP-MD5 (the simplest and weakest)
PEAP - (the 2nd simplest and pretty strong)
EAP-TLS or TTLS (the most difficult and strongest)
There are also LEAP and EAP-FAST. Both proprietary methods by Cisco.
Now,this link here
http://www.cisco.com/en/US/products/sw/secursw/ps5338/prod_configuration_examples_list.html
Explains how to setup ACS in conjunction with either PEAP or EAP-TLS. The thing with both is that it requires a Enterprise Certifcate Authority Server to authenticate the machines/user accounts.
If you only require 802.1x for wired connection, EAP-MD5 would be fine (and is simple enough... requires no CA).
For assistance on how to setup your switch with 802.1x, lookup you respective cisco switch and go the configuration guides. Most sections cover setting up 802.1x (including dynamic Vlan allocation)
I am in the middle of setting up our infrastructure with PEAP. Its secure enough to be used with wireless and wired connection and relatively simple enough to deploy in a medium to large enterprise.
I would also highly recommend reading the Wireless papers which discuss 802.1x EAP-TLS and PEAP.
http://www.microsoft.com/technet/security/guidance/peap_0.mspx
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide